MASC: Modelling Architectural Security Concerns
Paper in proceeding, 2015

Security decisions are an important part of software architecture design, and thus deserve to be explicitly represented in the design documentation. While UML is the best-known language for creating such documentation, it lacks security specific notations, which makes it difficult to represent the effect of the security decisions. Several security extensions for UML exist in the literature, but they represent security concerns at a lower level of abstraction, or only support a limited subset of security concerns. We propose a new notation, MASC, to model security concerns at the architectural level. It has been designed as an extension of UML, and is based on recurring security concepts that have been distilled from well-known security principles, goals, and patterns. By using our notation, a designer obtains a technique to express security concerns more explicitly in the architectural design documentation.

Computer Science

notation

security

software architecture

UML

MASC

Engineering

Author

L. Sion

K. Yskout

A. van den Berghe

Riccardo Scandariato

University of Gothenburg

W. Joosen

2015 IEEE/ACM 7th International Workshop on Modeling in Software Engineering

36-41

Subject Categories (SSIF 2011)

Software Engineering

DOI

10.1109/MiSE.2015.14

More information

Created

10/10/2017